South Korea, US warn of Gunra ransomware targeting healthcare, finance and critical infrastructure | #ransomware | #cybercrime


South Korean police and US cybersecurity agencies have issued a joint warning over Gunra ransomware, which has evolved into a ransomware-as-a-service operation. The malware has been used against critical infrastructure and sectors including healthcare, finance and manufacturing, prompting fresh calls for stronger network and account security.

South Korean authorities are warning businesses and public institutions to strengthen their cyber defences as the Gunra ransomware group expands its tactics and targets a wider range of organisations.

The Korean National Police Agency (KNPA) issued a joint cybersecurity advisory with US agencies including the Federal Bureau of Investigation (FBI) and the National Security Agency (NSA), detailing how the ransomware is being deployed and what organisations can look for when trying to detect an intrusion.

Gunra first emerged in 2025 but has since developed into a ransomware-as-a-service operation. Under this model, ransomware infrastructure and tools can be made available to other attackers, potentially allowing campaigns to reach more victims without the operators carrying out every stage themselves.

The latest advisory includes indicators of compromise and information about Gunra’s updated attack techniques, giving organisations specific information they can use to identify and block activity linked to the malware.

How Gunra attacks organisations

According to the advisory, Gunra operators have targeted critical infrastructure as well as organisations in sectors such as healthcare, financial services and manufacturing.

One route into a victim’s network involves exploiting vulnerabilities in systems exposed to attackers, including security equipment. Once inside, attackers can move further through the network before deploying ransomware and locking victims out of their data.

More from Tech

Gunra also uses a double-extortion approach. Rather than simply encrypting files and demanding payment for their recovery, attackers can first steal data and then threaten to release it publicly or sell it if the victim refuses to pay.

That creates two separate pressures for organisations: restoring access to their systems and preventing potentially sensitive information from being exposed.

The police did not provide details of specific victims in the latest warning, but said they are investigating attacks associated with Gunra.

The joint advisory reflects a broader effort by South Korean and US authorities to share information about ransomware campaigns and improve organisations’ ability to detect them before attackers can cause significant disruption.

Police urge companies to close basic security gaps

The KNPA said preventing the initial breach remains the most effective way to limit the damage caused by ransomware.

Organisations have been advised to reduce unnecessary external access to their networks and ensure that software and security systems receive the latest available patches. Keeping systems updated can help address vulnerabilities that attackers may otherwise exploit to gain an initial foothold.

Account security is another focus of the guidance. The police have urged organisations to strengthen access controls and introduce multi-factor authentication, which requires users to provide an additional form of verification beyond a password.

These measures are particularly important for organisations operating critical systems, where a successful ransomware intrusion could affect not only internal operations but also services relied upon by the wider public.

The authorities said organisations should also use the newly published indicators of compromise to check their environments for signs associated with Gunra.

South Korean police are continuing their investigation into attacks linked to the ransomware and said they will work with international partners to improve their ability to respond.

The warning comes as ransomware operators continue to adapt their methods, moving beyond simple file encryption towards attacks that combine data theft, extortion and exploitation of weaknesses in internet-facing systems. For organisations, the latest Gunra campaign is another reminder that preventing the first compromise can be just as important as responding after ransomware has already entered a network.



Click Here For The Original Source.

——————————————————–

..........

.

.